Koozali.org: home of the SME Server

SNORT and Acid

Offline MarkR

  • ***
  • 56
  • +0/-0
SNORT and Acid
« on: July 30, 2004, 01:54:34 PM »
Hi all,

I have been looking at installing snort and acid onto my SME server.
As i am running this server on a corp network, would you good people recommend installing Snort??
Are there any implications in doing so?

thanks
...

Offline Reinhold

  • *
  • 517
  • +0/-0
    • http://127.0.0.1
SNORT and Acid
« Reply #1 on: August 01, 2004, 12:22:13 PM »
Mark

Just do it ...

SNORT/ACID works,
it's easy and it does give some useful information on what's going on that you most likely will continue to read (which I assume to be unlikely with the syslog .-).

You may want to go to the Michel van Hees website:
http://vanhees.homeip.net/index.php?module=ContentExpress&func=display&ceid=19&meid=

be vigilant
Reinhold
............

RayG

SNORT and Acid
« Reply #2 on: August 01, 2004, 05:03:38 PM »
I use snort/acid/guardian at home and have had no problems with the combo in the past 8 or 10 months. Adding guardian to the mix is nice in that it simply drops traffic from sites that snort detects "attacks" from. This is more of a bandwidth saver than protection though. The stock e-smith package is pretty bulletproof. Snort does eat quite a bit of hard disk space with it's alert logs if you don't clean them out regularly.

I had to disable guardian on the system at work because it was blocking access from/to customers and vendors. Some sysadmins set their web/mail servers up to do rude things to verify our system isn't vulnerable to various attacks before allowing a connection. Sites can be added to guardians ignore file but that requires we be notified of a connection failure and our management won't allow for that. With guardian disabled, snort and acid are of less value. Manually sifting through the snort log is just not an activity I can spend time on. It's nice to see that the server is surviving continuous attack from all quarters but I can accept that fact without the cpu overhead and disk space requirements of snort.

Snort and acid are fun and give you that warm fuzzy feeling that the e-Smith distro is pretty secure. Without guardian, the fun quickly becomes a time consuming chore. I highly recomend snort/acid/guardian if you can work with occasional site that needs to be put in the guardian.ignore file.

Offline MarkR

  • ***
  • 56
  • +0/-0
SNORT and Acid
« Reply #3 on: August 02, 2004, 02:19:11 PM »
Thanks for feedback on snort...

I have installed it, but i was looking a the sysconfig files and noticed that the network card that it is monitoring is my lan card... is this correct?

thanks again
...

Offline Reinhold

  • *
  • 517
  • +0/-0
    • http://127.0.0.1
SNORT and Acid
« Reply #4 on: August 02, 2004, 09:27:44 PM »
Mark,

Of course you can monitor both ethernet cards ...
albeit in most cases it does make more sense to look at the gateway...that's where most trouble is supposed to come from!
Is your SME configured as "gateway and server"?

Have a look at this thread:
http://forums.contribs.org/index.php?topic=21470.0
...should answer most of your questions!

regards
Reinhold
............

Offline MarkR

  • ***
  • 56
  • +0/-0
SNORT and Acid
« Reply #5 on: August 05, 2004, 11:23:01 AM »
Yes my server is configured as a gateway & server

thanks
...